“Authorization with the MCP server failed”
claude.ai started a connector's sign-in and it did not finish: discovery, registration, the consent redirect or the token exchange failed, and the message does not say which. The three common causes: (1) Discovery fails or finds the wrong authorization server: no protected-resource metadata, a `resource` that is not the URL entered, or metadata only for a later `authorization_servers` entry. claude.ai then falls back to `/authorize` on the MCP server's own origin. To tell: The doctor fails at protected-resource metadata, `resource` or authorization-server metadata; the browser lands on <your-host>/authorize, as in #78. (2) The authorization server's metadata stops claude.ai: no S256 in `code_challenge_methods_supported`, an `issuer` that is not the URL it was looked up for, or no way to get a client ID. To tell: The doctor fails at PKCE, `issuer` or registration, or shows claude.ai blocked on registration. (3) Consent succeeds and the token exchange does not happen or is refused: with Entra, commenters trace it to the app registration type; claude.ai's documentation also names a token endpoint slower than 10 seconds and cross-host redirects. To tell: The doctor passes every step; your identity provider's sign-in log shows the consent and no token request, or an error on it. One command shows which step breaks: npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client claude-ai.
Check your server now
npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client claude-ai
Discovery only: no credential, no client registration. It prints the first broken step, whose it is, and the fix with the spec section.
Who prints it
claude.ai and Claude Desktop (a named connector shows "Authorization with <Name> failed"). 172 issues in anthropics/claude-ai-mcp contain this string (58 open), counted 8 October 2026.
The three causes, and how to tell them apart
- Cause 1. Discovery fails or finds the wrong authorization server: no protected-resource metadata, a `resource` that is not the URL entered, or metadata only for a later `authorization_servers` entry. claude.ai then falls back to `/authorize` on the MCP server's own origin.
The check fails at stepprm. The doctor fails at protected-resource metadata, `resource` or authorization-server metadata; the browser lands on <your-host>/authorize, as in #78. - Cause 2. The authorization server's metadata stops claude.ai: no S256 in `code_challenge_methods_supported`, an `issuer` that is not the URL it was looked up for, or no way to get a client ID.
The check fails at steppkce. The doctor fails at PKCE, `issuer` or registration, or shows claude.ai blocked on registration. - Cause 3. Consent succeeds and the token exchange does not happen or is refused: with Entra, commenters trace it to the app registration type; claude.ai's documentation also names a token endpoint slower than 10 seconds and cross-host redirects.
The check cannot see this one from outside: it happens after consent, or inside the client. The doctor passes every step; your identity provider's sign-in log shows the consent and no token request, or an error on it.
Public reports
- anthropics/claude-ai-mcp#632, opened 16 July 2026: first-party Entra servers: OAuth succeeds, Claude never exchanges the code at /token; open, 35 comments
- anthropics/claude-ai-mcp#78, opened 3 March 2026: Snowflake connector: sent to the origin's /authorize with scope=claudeai; 17 reactions, closed as not planned
- anthropics/claude-ai-mcp#215, opened 23 April 2026: the server issues the code and claude.ai never calls /token; closed as not planned
- anthropics/claude-ai-mcp#1100, opened 2 October 2026: GitLab.com: OAuth succeeds on GitLab, claude.ai shows "Authorization with Gitlab failed"; open
Keep checking
Other messages
- “Couldn't reach the MCP server”
- “Failed to discover OAuth metadata”
- “Dynamic Client Registration not supported”
- “Incompatible auth server: does not support dynamic client registration”
- “Issuer mismatch”
- “invalid_redirect_uri”
- “Connection expired”
- “token exchange failed”
Written 8 October 2026 from the public issues above. The sign-in check · MCP Liveness · Terms · Privacy